mbox-mcp
Allows reading and searching local Gmail archives exported via Google Takeout (.mbox format), enabling analysis of email history without a live connection.
Allows reading and searching local Thunderbird mail archives (.mbox format) by indexing exported messages.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mbox-mcpOpen my Gmail Takeout archive and tell me who I emailed most."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mbox-mcp
An MCP server for local email archives. Point it at a Google Takeout .mbox export or a folder of .eml files and ask Claude things like:
"Who did I email most in this archive?"
"Find the message where the landlord mentioned the lease renewal."
"Summarize my correspondence with bob@example.com from early 2026."
Everything stays on your machine. No OAuth, no app passwords, no IMAP connection, no cloud. Every other email MCP server connects to a live account — this one reads the archive files you already have, which is exactly what you want for the 15 years of Gmail sitting in a Takeout export.
Quick start
Claude Code
claude mcp add mbox -- npx -y mbox-mcpClaude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"mbox": {
"command": "npx",
"args": ["-y", "mbox-mcp"]
}
}
}Then: "Open C:\Takeout\Mail\All mail Including Spam and Trash.mbox and tell me about it."
Related MCP server: Mailing Manager MCP
Tools
Tool | What it does |
| Index an .mbox file or .eml directory: message count, date range, top senders |
| Search by keyword, sender, subject, date range — plus bounded body-text search |
| Fully parse one message: decoded body, headers, attachment names/sizes |
Built for large archives
A Takeout mbox is often multiple gigabytes with 100k+ messages. The design reads the minimum, lazily:
Streaming index — one pass in 8 MiB chunks, recording byte offsets; only the current message's first 16 KiB is ever held for envelope parsing (sender, subject, date, RFC 2047 decoding).
Full MIME on demand — reading a message parses just that message (postal-mime: nested multipart, charsets, quoted-printable/base64). Attachments are listed with names and sizes, never dumped into context.
Honest body search —
body_queryonly full-parses messages that already match your envelope filters, stops at a scan cap, and reports how many it scanned, so the model knows to narrow by sender or date first.Staleness-aware cache — archives are indexed once per process and re-indexed if the file changes.
Notes and limitations
mbox variants: Takeout and Thunderbird produce
mboxrd(bodyFromlines are quoted as>From), which splits cleanly. Plainmboxoarchives with unquoted bodyFromlines can over-split.Attachment contents are never returned or written anywhere.
PST/OST and Maildir are out of scope for now.
Development
npm install
npm test # offline tests — synthetic archives built in-suite
npm run build # tsc → dist/
node scripts/smoke.mjs # end-to-end: generates an archive, drives the server over stdioArchitecture: src/archive.ts (streaming indexer, header decoding, envelope filtering) and src/reader.ts (per-message MIME parsing) are pure logic; src/index.ts is the MCP wiring. The test suite includes a chunk-seam property test: indexing with pathological 17-byte chunks must produce an identical index to whole-file reads.
License
MIT
Available Tools
3 toolsget_messageRead a messageA
Fully parse one message by its id (from search_messages): headers, decoded text body (truncated if huge), and attachment names/types/sizes. Attachment contents are never returned.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Message id from search results | |
| path | Yes | Path to an .mbox file (e.g. a Google Takeout export) or a directory of .eml files |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility for behavioral disclosure. It clearly states that the body is decoded, may be truncated if huge, and that attachment contents are never returned. These are non-obvious behaviors that could surprise users, making this disclosure valuable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the action and scope. Every clause adds value: what is parsed, what is truncated, and what is excluded. There is no redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter tool with no output schema and no annotations, the description provides a complete contract. It specifies what is returned (headers, decoded body, attachment metadata), the truncation behavior, and the explicit exclusion of attachment contents. This is sufficient for an agent to invoke the tool confidently.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% for both parameters, with 'id' and 'path' already described in the input schema. The description adds no new parameter-level meaning beyond referencing 'from search_messages', which is already implied by the schema. Since the schema fully covers parameter semantics, the baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb ('Fully parse') and identifies the exact resource ('one message by its id'). It also distinguishes itself from sibling tools by referencing search_messages as the source of the id, making it clear this tool retrieves individual message details.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies a workflow: get an id from search_messages, then use get_message for full parsing. It also sets a clear limitation ('Attachment contents are never returned'), which suggests not using this tool for attachment content. However, it does not explicitly name alternatives or state when not to use beyond the attachment caveat.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
open_archiveOpen a local email archiveA
Index an .mbox file (Google Takeout, Thunderbird) or a directory of .eml files — entirely locally, nothing leaves the machine. Returns message count, date range, and top senders. Large archives are indexed once and cached.
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Path to an .mbox file (e.g. a Google Takeout export) or a directory of .eml files |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full transparency burden. It discloses key behaviors: 'entirely locally, nothing leaves the machine' (privacy), returns 'message count, date range, and top senders', and 'Large archives are indexed once and cached'. It doesn't detail side effects like where the index/cache is stored, but provides meaningful behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is three concise sentences, each adding distinct value: input formats + privacy, return values, and caching behavior. It is front-loaded with the core purpose and contains no wasted words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with one required parameter and no output schema, the description is remarkably complete. It covers input types, local processing guarantee, summary statistics returned, and caching behavior. No critical gaps for the tool's simplicity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and the 'path' parameter is fully described in the schema. The description restates similar information ('.mbox file' and '.eml' directory) but adds no new parameter semantics beyond what the schema already provides. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb 'Index' with a clear resource: '.mbox file' or 'directory of .eml files'. It distinguishes itself from sibling tools (search_messages, get_message) by focusing on loading/opening an entire archive rather than retrieving individual messages.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use this tool: to index an email archive for local processing. It provides clear context (supports Google Takeout and Thunderbird exports) but does not explicitly contrast with siblings or mention when not to use it. No exclusions or alternative tool names are given.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_messagesSearch the archiveA
Search indexed envelopes (from/to/subject/date). query matches sender and subject. body_query additionally full-parses candidate messages to search body text — it is capped, so narrow with sender/date filters first; the result reports how many candidates were scanned.
| Name | Required | Description | Default |
|---|---|---|---|
| from | No | Substring of the sender | |
| path | Yes | Path to an .mbox file (e.g. a Google Takeout export) or a directory of .eml files | |
| after | No | Only messages on/after this date, YYYY-MM-DD | |
| limit | No | Max results | |
| query | No | Keyword matched against sender and subject | |
| before | No | Only messages on/before this date, YYYY-MM-DD | |
| subject | No | Substring of the subject | |
| body_query | No | Substring searched in message bodies (bounded scan) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It discloses that query matches sender and subject, that body_query full-parses candidates, that it is capped, and that the result reports scanned candidates. This goes beyond basic read/write safety and explains performance-relevant behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with the core purpose, followed by a focused explanation of the key parameter behavior. Every sentence earns its place without repetition or fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has 8 parameters and no output schema, and the description covers the essential behavioral aspects: what is indexed, how query works, how body_query differs, and the cap/results. It does not fully describe the result structure beyond the scanned count, which would have been helpful without an output schema, but it is sufficient for an agent to use the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so baseline is 3. The description adds practical meaning to body_query by explaining its capped, full-parse nature and the advice to narrow filters first, which the schema does not convey. It also groups query as matching sender and subject, reinforcing schema but adding little new beyond body_query.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'Search' and the resource 'indexed envelopes' with a scope of from/to/subject/date. It differentiates from siblings like open_archive and get_message by focusing on searching across messages, not opening or retrieving a single message.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit usage guidance for the body_query parameter, advising to narrow with sender/date filters first due to the cap. It does not explicitly state when to use this tool vs alternatives, but the purpose is clear enough that an agent would know to use it for searching rather than opening or retrieving.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.1.1- First observed
get_message - First observed
open_archive - First observed
search_messages
TDQS
Each tool has a clearly distinct role: open_archive indexes, search_messages queries the index, get_message retrieves full message details. There is no functional overlap between tools.
All tool names follow the verb_noun pattern (open_archive, search_messages, get_message) with consistent snake_case, making the API predictable and easy to navigate.
Three tools is a reasonable, well-scoped number for a focused email archive server. Each tool is necessary and covers the core workflow without unnecessary bloat.
The core workflow of indexing, searching, and retrieving messages is covered, but there is no way to list or manage multiple open archives, and no delete/close operation for archives, which is a minor gap for long-running workflows.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Read, send, file and search email in any Gmail, Microsoft 365 or IMAP mailbox, plus its calendar.
Email infrastructure for AI agents — send, receive, search, and reply to email over MCP.
Connect any mailbox to Claude, ChatGPT & AI: read, send, reply, schedule & search emails.
Email inboxes for AI agents: send, receive, reply, search, and manage threaded email over MCP.
Related MCP Servers
- AlicenseAqualityDmaintenanceReads and searches Thunderbird mail from local mbox files and sends mail via SMTP using auto-discovered identities, filing copies in Thunderbird's Sent folder.91MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to manage multiple email accounts with secure credentials, local full-text search, thread-aware replies, and automation.23MIT
- AlicenseAqualityDmaintenanceEnables LLM clients to read and search email via IMAP with tools for listing folders, searching messages, and fetching message content. It supports pagination, snippets, and thread context, and is designed for local AI workflows.10MIT
- FlicenseAqualityDmaintenanceEnables local LLMs to search email via mu, keeping all data on-device for privacy.5-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/arose26/mbox-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server